Privacy Policy
Last updated: September 3, 2026
This policy explains what data GPI Connect (“we”, “us”) collects when you or your organization use our verifiable presence and live availability platform, why we collect it, and the choices you have. It is written to reflect what the product actually does today. If a future feature changes how data is handled, we will update this page and note the change.
1. Who this applies to
This policy covers GPI Connect's web application, the organization admin console, and the check-in flows used by members of an organization (students, staff, field agents) on their own devices. If you access GPI Connect on behalf of an institution or company, that organization is typically the data controller for the attendance records it collects about its members, and GPI Connect acts as the processor operating the underlying infrastructure.
2. Data we collect
- Account & profile data:Name, email or phone number, role/designation, and organization/department membership, provided at sign-up or by an administrator.
- Check-in location data:Precise device location is read only at the moment you perform an explicit check-in or update your availability status — never continuously in the background. Coordinates are used to validate geofence boundaries and are not published publicly; only a human-readable status tag (e.g. “Seminar Hall B-401”) is shown to others.
- Proximity (Bluetooth) session data:During Track 2 offline sessions, devices exchange short-range Bluetooth Low Energy signals to confirm physical presence. This data is used to build the attendance record for that session and is not used for tracking outside of an active session.
- Device & integrity signals:A device hardware signature, clock-drift measurements, and mock-location/rooting indicators are used to detect spoofing and proxy attendance. See our anti-proxy defenses for details.
- Usage & diagnostic data:Standard application logs and error reports (via our error-monitoring provider) to help us fix bugs and keep the service reliable.
3. How we use data
- Attendance records:To generate the official attendance/check-in record for your organization.
- Live availability:To power the opt-in “where is this person right now” status tag your organization enables.
- Anti-proxy integrity:To detect buddy punching, token replay, mock GPS, and other forms of attendance fraud described in our security matrix.
- Service operation:To authenticate you, sync offline records once connectivity returns, and provide support.
- Product reliability:To diagnose crashes and performance issues via aggregated, pseudonymized error reports.
4. What we do not do
- No background tracking:We do not read or store your location outside of an explicit check-in or status update.
- No public GPS coordinates:Exact coordinates are never shown to other members — only the human-readable tag you choose to publish.
- No selling of data:We do not sell personal data to third parties or data brokers.
5. Data sharing
We share data with the organization you belong to (for attendance and availability purposes), and with infrastructure and service providers who process data on our behalf under contract — for example, cloud hosting, database, authentication, transactional email, and error-monitoring providers. We do not permit these providers to use your data for their own purposes.
6. Data retention
Attendance and availability records are retained for as long as your organization's account is active, plus a reasonable period afterward for record-keeping and dispute resolution, unless your organization requests earlier deletion or applicable law requires a different retention period. Offline records queued on a device are held locally for up to 7 days before syncing, after which they are cleared from the device.
7. Cookies & local storage
We use one essential session cookie to keep you signed in to the admin console — it is required for the Service to function and is not used for advertising or cross-site tracking. Some pages also use your browser's local storage to remember lightweight preferences (such as an open panel or filter) on your own device; this data stays on your device and is not sent to us.
8. Security
Data is encrypted in transit and at rest. Offline attendance entries are signed with HMAC and independently re-validated by the server on sync, so a tampered local record is detected rather than silently trusted. Access to organization data is isolated per organization and limited to authorized administrators.
9. Your rights
Depending on your organization's policies and applicable law, you may have the right to access, correct, export, or request deletion of your personal data. Start by contacting your organization's administrator, or reach us directly at support@gpiconnect.com.
10. Children's privacy
GPI Connect is used in educational settings and may process attendance data for minors on behalf of a school or university acting as the responsible data controller. We rely on that institution to obtain any consent required under applicable law before enrolling a minor.
11. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by updating the “Last updated” date above.
12. Contact
Questions about this policy can be sent to support@gpiconnect.com.